PT-2026-60856 · WordPress · Wordpress
CVE-2026-63030
·
Published
2026-07-17
·
Updated
2026-09-05
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress versions 6.9.0 through 6.9.4
WordPress versions 7.0.0 through 7.0.1
Description
A route confusion issue in the REST API batch endpoint, combined with a SQL injection in the
WP Query class, allows a remote attacker to execute arbitrary code and gain unauthorized access to confidential information. The issue stems from the get items() function, where a desynchronization occurs between the permission check array, the allowed endpoints list, and the execution array. Additionally, the WP Query class fails to properly protect the SQL query structure when processing the author not in variable.Recommendations
Update WordPress versions 6.9.x to 6.9.5.
Update WordPress versions 7.0.x to 7.0.2.
Exploit
Fix
DoS
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wordpress